policy · Effective Jan 1, 2025
MX regulates AI through Federal Artificial Intelligence legislative initiatives and Senate commission proposal (2023–2025).
Federal Artificial Intelligence legislative initiatives and Senate commission proposal (2023–2025) · effective 2025
Updated 60 days ago · 2 sources · confidence: medium
Overview
Mexico’s overall approach to artificial intelligence (AI) regulation has evolved significantly from early exploratory white papers in 2018 to a concentrated legislative push for a binding federal framework between 2023 and 2025. Historically, the Mexican government relied on soft-law instruments, such as the 2018 'General Principles and Impact Assessment Guide for AI in the Federal Public Administration,' which established a foundation for ethical use, transparency, and human rights. However, the rapid advancement of generative AI and the global shift toward prescriptive regulation (notably influenced by the EU AI Act) have prompted Mexican lawmakers to seek a more robust statutory basis. The current philosophy, championed by the federal executive and various parliamentary commissions, emphasizes 'technological sovereignty,' aiming to reduce dependence on foreign proprietary models while fostering domestic innovation that respects Mexico's unique cultural and linguistic identity. The regulatory landscape is currently in a state of high activity, with the 2024–2030 administration prioritizing digital transformation as a pillar of national development. This is evidenced by the creation of specialized agencies like the Digital Transformation and Telecommunications Agency (ATDT) and the elevation of the science council to a full Ministry (SECIHTI). Mexico’s maturity level is transitioning from 'nascent' to 'emerging' as it moves beyond mere policy declarations into the realm of constitutional amendments and criminal code reforms. The overarching goal is to create a 'General Law' that harmonizes AI use across federal, state, and municipal levels, ensuring that technological adoption does not exacerbate existing social inequalities or compromise the privacy and security of Mexican citizens.
Regulatory approach
Mexico is shifting from a fragmented, sectoral approach toward a centralized, horizontal regulatory model. While early efforts were largely confined to administrative guidelines for the public sector, the current legislative trend favors a comprehensive 'General Law on Artificial Intelligence.' This proposed framework typically adopts a risk-based classification system, categorizing AI applications into minimal, limited, high, and prohibited risks. Prohibited uses under discussion include mass biometric surveillance in public spaces without judicial warrants, social scoring systems, and AI-driven manipulative profiling. High-risk systems, such as those used in healthcare, credit scoring, or public security, are expected to face rigorous transparency, documentation, and conformity assessment requirements before they can be deployed in the Mexican market. This horizontal ambition is complemented by targeted sectoral interventions. For instance, there are specific bills addressing the use of AI in public security, the protection of dubbing performers in the cinematography industry, and the criminalization of AI-generated non-consensual intimate content (deepfakes). The approach is increasingly binding; while the 2021 National Digital Strategy (EDN) provided a mandatory roadmap for federal agencies, the new wave of legislation seeks to impose civil and criminal liabilities on private actors and developers. This dual-track strategy—combining a broad ethical framework with specific penal and labor protections—reflects a desire to balance the promotion of a digital economy with the mitigation of specific harms identified by civil society and international bodies. The governance of AI in Mexico is currently undergoing a structural reorganization to centralize authority within the executive branch. The primary body responsible for digital policy has traditionally been the National Digital Strategy Coordination (CEDN) within the Office of the Presidency. However, the 2025 implementation of the 'Plan México' has introduced the Digital Transformation and Telecommunications Agency (ATDT) as the leading entity for coordinating digital infrastructure, sovereign AI development, and government-wide interoperability. The ATDT is tasked with overseeing the National AI Laboratory (LNIA), which serves as a hub for research, model evaluation, and the training of human capital in public-interest AI applications. Complementing the ATDT is the Ministry of Science, Humanities, Technology, and Innovation (SECIHTI), which provides the scientific and ethical oversight for AI research and development. SECIHTI is expected to play a critical role in defining the technical standards and ethical guidelines that will govern the 'General Law.' Additionally, the National Institute for Transparency, Access to Information, and Protection of Personal Data (INAI) remains the primary autonomous regulator for data protection. INAI’s mandate includes ensuring that AI systems deployed by both public and private entities comply with the Federal Law on Protection of Personal Data, particularly regarding automated decision-making and the right to an explanation. The interaction between these executive agencies and the autonomous INAI will be a defining feature of Mexico's AI governance model as it balances administrative efficiency with independent oversight.
Enforcement & penalties
Enforcement mechanisms for AI in Mexico currently reside within existing administrative and criminal frameworks, though AI-specific sanctions are a core component of pending legislation. Under the current Federal Law on Protection of Personal Data in Possession of Private Parties (LFPDPPP), INAI can impose significant administrative fines for privacy violations, which can reach millions of pesos depending on the severity of the breach. For public servants, the General Law of Administrative Responsibilities provides a pathway for sanctions ranging from private warnings to dismissal and disqualification for the misuse of digital assets or the unauthorized processing of sensitive information. The 2025 legislative agenda introduces more severe penal consequences for AI-related harms. Proposed amendments to the Federal Penal Code seek to establish prison sentences ranging from six months to four years for the 'improper use' of generative AI, which includes the creation of deceptive deepfakes intended to cause reputational harm or influence democratic processes. Furthermore, the proposed 'General Law on AI' contemplates the creation of a National Registry of AI Systems; failure to register high-risk systems or providing false information during the conformity assessment process could result in substantial fines and the mandatory suspension of the AI system's operation. Appeals against these sanctions are typically handled through the Federal Court of Administrative Justice (TFJA) or through 'amparo' proceedings in the federal judiciary to protect constitutional rights against arbitrary state action.
Data protection
Mexico possesses a robust dual-track data protection framework that serves as the bedrock for AI regulation. The private sector is governed by the Federal Law on Protection of Personal Data in Possession of Private Parties (LFPDPPP), while public sector entities are subject to the General Law on Protection of Personal Data in Possession of Obligated Subjects (LGPDPSOB). Both laws are enforced by INAI and emphasize principles of legality, consent, information, quality, purpose, loyalty, proportionality, and accountability. These principles are directly applicable to AI training and deployment, particularly regarding the 'right to opposition' and the 'right to explanation' when individuals are subject to purely automated decisions that produce legal effects. A significant challenge in the Mexican framework is the lack of specific 'data localization' requirements, although the National Digital Strategy (EDN) emphasizes 'technological sovereignty,' which encourages the storage of sensitive government data on national infrastructure. The proposed AI regulations seek to harmonize these data protection laws with the requirements of large-scale machine learning, potentially introducing 'sandboxes' for data processing and clearer guidelines on the use of publicly available data for model training. Furthermore, the 2025 initiatives emphasize the protection of biometric data, proposing strict prohibitions on the non-selective extraction of facial images from the internet for the purpose of training surveillance algorithms without the explicit consent of the data subjects.
Sector-specific rules
Sectoral AI regulation in Mexico is emerging in areas where the impact on human rights and labor is most acute. In the realm of public security, a 2025 initiative proposes to amend the Federal Law Against Organized Crime to authorize the use of AI for predictive analytics, communications monitoring, and facial recognition. However, this proposal has sparked significant debate regarding the need for judicial oversight and the prevention of biometric mass surveillance. The bill suggests that the Ministry of Public Security (SSPC) would oversee these tools, but civil society groups are advocating for mandatory algorithmic impact assessments to prevent discriminatory policing outcomes. In the cultural and creative industries, Mexico is a pioneer in proposing protections for dubbing performers against AI voice cloning. A 2025 bill seeks to amend the Federal Copyright Law and the Federal Labor Law to ensure that AI cannot be used to replace human performers without explicit written consent and fair compensation. Similarly, the education sector is seeing proposed reforms to the General Education Law to mandate the inclusion of AI ethics and digital literacy in national curricula. These sectoral rules demonstrate Mexico's preference for 'targeted' interventions that address the specific vulnerabilities of different industries while the broader horizontal framework is being finalized. This approach ensures that immediate harms are addressed while the long-term constitutional and general law processes continue to mature.
International alignment
Mexico’s AI regulatory strategy is heavily influenced by international standards and multilateral agreements. The country is a signatory to the OECD Principles on Artificial Intelligence and has actively participated in the development of the UNESCO Recommendation on the Ethics of Artificial Intelligence. These instruments are frequently cited in the 'exposition of motives' for Mexican bills, particularly the emphasis on human-centric AI, transparency, and accountability. Mexico also maintains a strong interest in aligning its framework with the EU AI Act to facilitate digital trade and ensure that Mexican AI developers can access the European market by meeting comparable safety and ethical standards. Furthermore, Mexico has engaged in bilateral cooperation, notably with the United Kingdom, which commissioned the foundational 2018 white paper 'Towards an AI Strategy in Mexico.' The country also looks toward the United States' executive orders on AI for benchmarks on cybersecurity and model security, especially within the context of the USMCA (T-MEC) agreement. As a member of the G20 and the Pacific Alliance, Mexico is positioning itself as a regional leader in AI governance, advocating for a 'Global South' perspective that prioritizes inclusive development and technological autonomy. This international alignment is not merely formal; it is a strategic necessity to ensure that Mexico’s domestic regulations are interoperable with the global digital economy while protecting its sovereign interests and cultural identity.
What's next
The immediate future of AI regulation in Mexico hinges on the successful passage of the constitutional reform to Article 73. If approved, this amendment will trigger a mandatory 180-day period for the Congress to enact the 'General Law on Emerging, Disruptive Technologies and Artificial Intelligence.' This law is expected to be the most significant piece of technology legislation in Mexico’s history, establishing the definitive risk-classification system, the National AI Council, and the mandatory registry for high-risk applications. Stakeholders expect this law to introduce formal 'regulatory sandboxes' to allow for controlled innovation in sectors like fintech and healthtech. Another key development to watch is the operationalization of the National AI Laboratory (LNIA) under the ATDT. The LNIA is expected to publish the first set of national technical standards for 'Sovereign AI' models, which will likely influence public procurement rules and set a benchmark for private sector adoption. Additionally, the ongoing debate regarding the 'simplification' or potential absorption of autonomous bodies like INAI into the central government could fundamentally alter the enforcement landscape for data protection and AI oversight. Lawmakers are also expected to introduce further refinements to the Federal Labor Law to address the impact of AI on job displacement and the 'right to disconnect' in an increasingly automated workforce, ensuring that the digital transition remains inclusive and socially responsible.
policy · Effective Jan 1, 2025
policy · Effective Jan 1, 2025
sectoral
Coordination of national digital strategy, telecommunications, and sovereign AI development.
data_protection
Protection of personal data and guarantee of the right to access public information.
advisory
Promotion of scientific research, technological development, and ethical oversight of emerging tech.
advisory
Elaboration and follow-up of the National Digital Strategy across the Federal Public Administration.
May 21, 2026 · news
San Luis Potosí state prosecutor’s office confirms arrests of two journalists, alleging "deliberate and illegal manipulation of the digital identity of the victim"
Open source →Apr 20, 2026 · news
Mexico proposes AI rules that could imprison violators
Open source →Feb 23, 2026 · news
Mexican Chamber of Deputies receives initiatives from the President to protect artists' rights against AI misuse
Open source →Jan 28, 2026 · news
Mexico SECIHTI unveils 10 principles for ethical AI deployment
Open source →policy · Effective Jan 1, 2025
policy · Effective Jan 1, 2025
policy · Effective Jan 1, 2025
policy · Effective Jan 1, 2025
policy · Effective Jan 1, 2025
policy · Effective Jan 1, 2025
policy · Effective Jan 1, 2025
regulation · Effective Jan 1, 2023
policy · Effective Jan 1, 2023
regulation · Effective Jan 1, 2021
guideline · Effective Jan 1, 2018
act · Effective n/a
A proposed initiative to establish (1) structures and ethical standards for the development, research, and use of AI in Mexico; and (2) a Mexican Council for Ethics in Artificial Intelligence and Robotics.
Sep 29, 2025 · law_amended
Mexico is working on a law to regulate the use of AI in dubbing, animation, and voiceovers
Aug 31, 2025 · news
Mexico Supreme Court rules that works created by AI cannot be granted copyrighted
Open source →Aug 3, 2025 · news
2025 APEC Digital and AI Ministerial Statement
Open source →Oct 27, 2024 · news
Global data protection authorities issue statement on data scraping, covering AI
Open source →Feb 26, 2024 · law_amended
Mexico Proposes Groundbreaking AI Regulation Bill Aligned with EU, Chile Models
Open source →